Vulnerabilities/

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

Severity:
Low

Description

Papra’s webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal addresses — loopback, link-local, and RFC-1918 ranges. The SSRF protection validates the registered webhook URL but ignores redirect destinations.

Recommendation

Update the @papra/webhooks package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@papra/webhooks
Anything's wrong? Let us know Last updated on June 10, 2026